Live data from Hacker News

Viewing profile — tsteenbe

tsteenbe

HN member
Joined
Mon, Jan 06, 2020, 10:48 AM UTC
HN karma
45
Public activity
7 items

About tsteenbe

GitHub: https://github.com/tsteenbe LinkedIn: https://linkedin.com/in/tsteenbe

Recent public activity

  1. comment
    Comment #43087333

    This is why several German automotive OSPOs are working together to build OSS Review Toolkit (ORT) - it kinda glues various open source tools like ScanCode but adds features like t…

  2. comment
    Comment #32123456

    > Do HN got a recommendation for other CLI based SBOM generators? Try ORT https://github.com/oss-review-toolkit/ort (full disclosure I am one of its maintainers and also the lead o…

  3. comment
    Comment #26790102

    Good catch I missed that openCVE is Business Source License which I actually do not consider to be open source.

  4. comment
    Comment #26789945

    Are you aware of https://github.com/nexB/vulnerablecode ? which offers a similar solution, is also open source and written in Python.

  5. comment
    Comment #21968584

    > It makes license scanning a doddle. As someone working in the field of license compliance (leading an Open Source Program Office) and dealing with the licensing of tens of thousa…

  6. comment
    Comment #21968406

    > A trivial solution would be to create a crowd-sourced dependency vetting platform. Such a platform is already being developed by various organizations, see https://clearlydefined…

  7. comment
    Comment #21968296

    If you want to do license compliance for various package managers then I recommend you checkout https://github.com/heremaps/oss-review-toolkit . Full disclosure: I am one of the ma…